Skip to content

Add native Cloud Hypervisor sandbox runtime support (parity with docker-sbx) #52118

Description

@lpcox

Context

gh-aw-firewall (AWF) now ships a Cloud Hypervisor v53.0 microVM runtime as a documented preview: --container-runtime cloud-hypervisor (gated behind --cloud-hypervisor-preview), supported only on GitHub-hosted Ubuntu x86_64 KVM runners. It reached a fully green live-KVM CI suite (15 behavioral/security cases: allowed/blocked domains, direct-egress/TCP/DNS/metadata blocking, mandatory API-proxy reflect with secret isolation, workspace copy-back, exit-code/timeout/SIGTERM handling, partial-start rollback, and no netns/veth/TAP/cgroup/process residue) in github/gh-aw-firewall#7227, and github/gh-aw-firewall#7247 now publishes its guest artifact bundle (kernel, rootfs, AWF supervisor) as a pinned, SHA256-verified GitHub Release asset (cloud-hypervisor-test-x86_64.tar.gz + SHA256SUMS/manifest.json/sbom.spdx.json), mirroring Firecracker's existing release channel. The upstream Cloud Hypervisor VMM binary itself was already a genuine public, SHA256-pinned upstream release.

Today, gh-aw's compiler has zero native support for either Firecracker or Cloud Hypervisor — only gvisor and docker-sbx currently exist as sandbox.agent.runtime values in generated workflows. This issue requests adding Cloud Hypervisor as a first-class sandbox.agent.runtime option, giving it operational parity with docker-sbx.

Gap analysis (docker-sbx generated step sequence as the parity template)

Decompiling this repo's own gh-aw-authored smoke-docker-sbx.md.lock.yml, docker-sbx today generates:

  1. KVM availability preflight (lsmod | grep kvm, /dev/kvm existence) with actionable errors.
  2. Docker Hub secret preflight (DOCKER_PAT/DOCKER_USERNAME).
  3. Install via apt-get install docker-sbx + chmod 666 /dev/kvm.
  4. Daemon start + docker login/sbx login + sbx policy init allow-all + template image pull.
  5. Throwaway smoke-boot (sbx create/exec uname -a/stop).
  6. Credential refresh immediately before the real run (OAuth tokens expire between steps).
  7. Final invocation: bare --container-runtime sbx (no artifact-path/digest flags — sbx self-manages its own binary distribution via APT).

To reach equivalent parity for Cloud Hypervisor, gh-aw needs:

Gap Description
New enum value Register cloud-hypervisor as a valid sandbox.agent.runtime value in the compiler's schema/validation.
Host-eligibility preflight generation Generate a step asserting GitHub-hosted Ubuntu x86_64 + /dev/kvm availability (narrower requirement than docker-sbx's KVM check — no self-hosted/ARC/ARM64/macOS claim should be made, matching AWF's own support statement).
Artifact provisioning Now unblocked by #7247: generate a step that downloads/verifies the pinned cloud-hypervisor-test-x86_64 release asset (tarball + SHA256SUMS) for a given AWF version, analogous to how docker-sbx installs its own binary via APT.
Invocation flag templating Generate --container-runtime cloud-hypervisor --cloud-hypervisor-preview plus the artifact path flags (--cloud-hypervisor-binary, --cloud-hypervisor-kernel, --cloud-hypervisor-rootfs, --cloud-hypervisor-supervisor) and matching --cloud-hypervisor-*-sha256 digest-pinning flags, using the manifest/SHA256SUMS values from the downloaded release asset as the source of truth.
Digest-pinning source Use manifest.json/SHA256SUMS from the GitHub Release asset (see #7247) as the canonical digest source — do not re-derive or hand-maintain digests in gh-aw itself.
Schema/docs Document the new runtime value, its GitHub-hosted-only limitation, and its preview status in gh-aw's own schema/docs, consistent with AWF's docs/awf-config-spec.md and docs/cloud-hypervisor-foundation.md.

Notes / constraints to carry over

  • This is a preview feature in AWF; gh-aw's generated workflows/docs should surface that status rather than presenting it as a stable production runtime.
  • Support is intentionally narrow: GitHub-hosted Ubuntu x86_64 runners only. Do not generate host-eligibility logic implying local/macOS/self-hosted/ARC/ARM64 support.
  • Firecracker is still present in AWF alongside Cloud Hypervisor (no deprecation yet), so this issue is additive and does not require removing or altering any existing docker-sbx/gvisor code paths.

References

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions